CVE-2007-2792
Yet another Newsletter Component (YaNC) < 1.5 beta 3 - SQL Injection via listid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-2792. PoCs published by snakespc, Mehmet Ince.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Joomla's com_yanc component, allowing unauthorized extraction of user credentials from the jos_users table via a crafted UNION SELECT query.
Description
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Joomla's com_yanc component, allowing unauthorized extraction of user credentials from the jos_users table via a crafted UNION SELECT query.
This is a writeup describing a blind SQL injection vulnerability in Mambo com_yanc v1.4 beta. It provides an example exploit URL and a Google dork for finding vulnerable targets.